BlackTree Security · Infrastructure · Automation · AI

Uruguay Created a Legal Path for AI Regulatory Sandboxes

Uruguay published Decree 276/025 on 10 December 2025. It creates a governance framework for controlled test environments and data spaces, giving innovative projects, including uses of data and artificial intelligence, a supervised path between laboratory and full-scale deployment.

A regulatory sandbox is sometimes described as a place where normal rules do not apply. Uruguay’s decree takes a more disciplined approach. A controlled environment is temporary, bounded and monitored. Any conditioned exception, special authorisation or public support must sit inside an approved plan and governance structure.

The framework implements Articles 74 and 75 of Law 20,212 and gives AGESIC a central approval role, supported by technical evaluation committees.

A sandbox begins with a defined proposal

One or more public entities may promote a controlled test environment and present it to the Technical Evaluation Committee. Approval requires a reasoned decision by the Agency for Electronic Government and the Information and Knowledge Society.

The proposal must define the project, participants, duration, scope, risks, safeguards, monitoring, exit conditions and accountability. Those elements make the sandbox useful. Without boundaries and measurable questions, a pilot can drift into ordinary production without the evidence expected from either.

The evaluation committee sets the operating rules

The committee establishes criteria for creating, regulating and monitoring test environments and data spaces. It can define protocols, reporting duties and minimum participant requirements, and it evaluates proposals before AGESIC approval.

Committees may include public bodies, academia, the private sector and civil society. That mixed expertise is important for AI projects, where legal compliance, technical performance and social impact cannot be evaluated by one discipline alone.

Data spaces need governance as well as infrastructure

The decree also addresses data spaces. A data space is not merely a shared storage location. It needs rules for participation, access, permitted use, quality, interoperability, security and accountability.

Projects involving personal data remain subject to data-protection requirements. A sandbox can test how a rule or technology operates, but it does not erase fundamental rights, dignity or the need for proportionate safeguards.

Safe innovation requires an exit

A good sandbox produces a decision. The project may proceed under ordinary rules, need further controls, require regulatory change or stop because the risk is unacceptable. Participants should know in advance what evidence will support each outcome.

Exit planning must also address data deletion or migration, user communication, continued support and any people affected during the test. Ending a pilot does not end responsibility for its consequences.

What project teams should do

  1. Define the precise legal or operational uncertainty the controlled test will answer.
  2. Limit participants, data, duration, functionality and affected population.
  3. Set measurable safety, fairness, privacy, security and performance criteria.
  4. Establish independent monitoring, incident escalation and periodic reporting.
  5. Plan transition, remediation and termination before the test begins.

The value is controlled learning

Decree 276/025 gives Uruguay a legal structure for learning from innovative projects without confusing experimentation with exemption. Its value will depend on whether sandboxes generate evidence that regulators, participants and the public can use when deciding what should scale.

Official sources

This article provides general information and is not legal advice.

Continue the series: LATAM Cyber & Digital Law Series index

Leave a Reply

Your email address will not be published. Required fields are marked *